Home / Insights / EU AI Act
Classification · Provider vs deployer · Risk tiers · Annex III

Provider or deployer, high-risk or not: the two questions that set your AI Act obligations.

Every duty in the AI Act flows from two answers — which role you occupy, and which risk tier your system sits in. Get these two right and everything else follows. Get them wrong and you either over-comply or walk into an enforcement gap.

Work out where you land ↗ 20 minutes, no commitment
Question one — the role
Art. 3

Who are you in the chain?

Provider, deployer, importer or distributor. The same system carries entirely different duties depending on which of these you are.

Question two — the risk
Art. 5, 6, 50, 51

What tier is the system?

Prohibited, high-risk, limited-risk (transparency) or minimal. The tier decides how heavy the obligations are — or whether the system is allowed at all.

Most AI Act confusion comes from skipping straight to "what do I have to do" without first fixing "what am I, and what is this system." Those two questions are the whole framework. This is the map — not legal advice, but the structure you need before any of the compliance work makes sense.

Question one: which role do you occupy?

The Act (Article 3) assigns duties by role, not by company. The heaviest obligations fall on the provider; the deployer carries a lighter, use-focused set. Importers and distributors sit in between as gatekeepers.

Heaviest duties
ProviderDevelops an AI system or general-purpose model — or has it developed — and places it on the market or into service under its own name or trademark, paid or free. Carries the conformity, documentation and quality-management obligations.
Use-focused duties
DeployerUses an AI system under its own authority in a professional capacity. Obligations centre on using the system as instructed, human oversight, and monitoring — not on building conformity from scratch.
Gatekeeper
ImporterEstablished in the Union, places on the market a system carrying the name or trademark of a provider established outside the EU. Must verify the provider did the conformity work.
Gatekeeper
DistributorAnyone else in the supply chain who makes a system available on the Union market. Must check the required marking and documentation are present.
The trap that catches deployers

A deployer can silently become a provider.

Under Article 25, if you put your own name or trademark on a high-risk system, substantially modify one already on the market, or change its intended purpose so it becomes high-risk, you take on the provider's obligations — the heavy set. Fine-tuning a model and shipping it as your own is the classic way a "we only use it" company wakes up as a provider.

The non-EU dimension: you may also need a representative.

If you are a provider established outside the Union, role classification carries an extra consequence. Before placing a high-risk system on the EU market you must appoint an authorised representative established in the Union (Article 22); the same requirement applies to providers of general-purpose AI models under Article 54 — and that one has been in force since August 2025. Which role you occupy determines whether this obligation is yours at all.

Question two: which risk tier?

The Act sorts systems into four tiers. Obligations scale with the tier — and the top tier is not a heavy-compliance category, it is a ban.

Article 5Unacceptable — prohibitedA short list of practices banned outright. Not "high compliance" — not allowed.
Art. 6 & Annex III / IHigh-riskPermitted, but subject to the full conformity, documentation, oversight and registration regime.
Article 50Limited-risk — transparencyAllowed, with a duty to tell people they are dealing with, or looking at, AI output.
Minimal-riskEverything else. No specific obligations under the Act; voluntary codes encouraged.

The top tier: prohibited practices.

These have applied since 2 February 2025. If a system does any of the following, no amount of documentation makes it compliant.

Article 5 — banned outright
Subliminal or manipulative techniques that materially distort behaviour and cause harm.
Exploiting vulnerabilities of age, disability or socio-economic situation to distort behaviour.
Social scoring — evaluating or classifying people over time based on behaviour or traits, leading to detrimental treatment.
Untargeted scraping of facial images from the internet or CCTV to build recognition databases.
Emotion recognition in the workplace and in education institutions (narrow safety/medical exceptions aside).
Biometric categorisation to infer sensitive attributes such as race, political opinion or sexual orientation.
Real-time remote biometric identification in public spaces for law enforcement, save for narrowly defined exceptions.
Predictive policing assessing the risk of offending based solely on profiling or personality traits.

The heavy tier: what actually counts as high-risk.

A system is high-risk on two routes. Annex I — it is a safety component of a product already regulated under EU harmonisation law (machinery, medical devices, toys, vehicles and so on). Or Annex III — it falls into one of eight listed use areas. The Annex III list is where most software companies discover they are in scope.

1
BiometricsRemote biometric identification, biometric categorisation by sensitive attributes, emotion recognition (where permitted).
2
Critical infrastructureSafety components in the management of digital infrastructure, road traffic, water, gas, heating or electricity.
3
Education & vocational trainingAdmission and assignment, evaluating learning outcomes, steering learning, proctoring exams.
4
Employment & workersRecruitment and selection, filtering applications, evaluating candidates, promotion / termination and task allocation, performance monitoring.
5
Essential servicesEligibility for public benefits, creditworthiness and credit scoring, life and health insurance risk and pricing, emergency call triage.
6
Law enforcementVictim-risk assessment, polygraphs, evidence reliability, offending-risk and profiling — where permitted under law.
7
Migration & border controlPolygraphs, risk assessment of entrants, examination of asylum / visa / residence applications, identification.
8
Justice & democratic processAssisting a judicial authority in applying law to facts; influencing elections, referenda or voting behaviour.
The filter most people miss

Falling in an Annex III area does not automatically make you high-risk.

Article 6(3) carves out systems that do not pose a significant risk to health, safety or fundamental rights — for example a narrow procedural task, or work that merely improves the result of a completed human activity. But a system that profiles people is always high-risk. If you intend to rely on the exemption, that decision has to be documented and registered, not assumed — and specific carve-outs exist (identity verification, fraud detection, campaign logistics) that are narrower than they sound.

The tier everyone underestimates: transparency.

Article 50 is the tier that catches ordinary software — chatbots, generative tools, synthetic media — that is nowhere near high-risk. It is a disclosure regime, and its deadline lands before the high-risk one.

  • Systems that interact with people must make clear a person is dealing with AI, unless it is obvious from context.
  • Generated or manipulated content — text, image, audio, video — must be marked as artificially produced in a machine-readable form.
  • Deepfakes must be labelled as such, and AI-generated text published to inform the public on matters of public interest must be disclosed.
  • Emotion recognition and biometric categorisation require informing the people exposed to them.
The date that lands first

Transparency obligations apply from 2 December 2026.

Any product that generates synthetic content for EU users is in scope, regardless of risk classification — and this deadline arrives a full year before the high-risk one. It is the AI Act obligation the broadest set of companies will meet first.

The separate track: general-purpose AI models.

GPAI models run on their own classification, parallel to the system tiers. A provider of a general-purpose model carries baseline obligations — technical documentation, a copyright policy, a training-data summary. A model crosses into the systemic-risk category when the compute used to train it exceeds 1025 FLOPs, which adds model evaluation, adversarial testing, risk mitigation and incident reporting. GPAI obligations, including the Article 54 representative duty for non-EU providers, have applied since August 2025.

Putting the two axes together.

Your obligations are the intersection of the role and the tier. The same system produces very different duties depending on where you stand.

If you are a......and the system is high-risk...and it is transparency-tier
ProviderRisk management, technical docs, quality management, conformity assessment, registration, EU representative if non-EUDesign the disclosure / marking into the system
DeployerUse as instructed, ensure human oversight, monitor, keep logs, inform affected people; run a fundamental-rights impact assessment where requiredInform the people exposed (e.g. label the deepfake, disclose the chatbot)
Importer / DistributorVerify conformity, marking and documentation before making it availableCheck the transparency marking is present

When each obligation actually bites.

Tier / obligationApplies fromStatus
Prohibited practices, AI literacy2 February 2025In force
GPAI model obligations (incl. non-EU representative)2 August 2025In force
Transparency & labelling (Art. 50)2 December 2026Next up
High-risk — Annex III systems2 December 2027Deferred
High-risk — Annex I products2 August 2028Deferred

The high-risk dates reflect the 2026 simplification package. The penalty ceiling underneath all of this is real: up to €35 million or 7% of worldwide turnover for prohibited practices, with lower caps for other breaches. Spain has gone further than most member states in building the enforcement architecture — AESIA, its dedicated AI supervisor, has been operational since 2024.

The takeaway

Answer the two questions first. Everything else is downstream.

Role and tier are legal determinations of fact, not marketing choices — and the most expensive AI Act mistakes are made by companies that assumed one answer and built on it. Settling them early, with the classification documented, is what turns the AI Act from an open-ended worry into a defined, and deferred, workstream.

Based on Regulation (EU) 2024/1689 (Official Journal text of 13 June 2024) and the 2026 simplification package; Annex III wording paraphrased from the official list. General information, not legal advice — role and risk classification are fact-specific determinations that require professional assessment of the actual system and its intended purpose.

Two questions decide everything. Answer them before you build the compliance.

Book a free call ↗
20 minutes · No commitment · Straight answers